CVE-2026-63767
CRITICALktransformers Unauthenticated Pickle Deserialization RCE via ZMQ
Title source: cnaDescription
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious __reduce__ methods embedded in crafted pickle payloads to execute arbitrary shell commands as the server process.
References (4)
Core 4
Core References
Patch patch
Patch Commit
https://github.com/kvcache-ai/ktransformers/commit/def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/ktransformers-unauthenticated-pickle-deserialization-rce-via-zmq
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/kvcache-ai/ktransformers/issues/2087
Issue Tracking issue-tracking
patch
Pull Request
https://github.com/kvcache-ai/ktransformers/pull/2091
Scores
CVSS v3
9.8
EPSS
0.0074
EPSS Percentile
51.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
kvcache-ai/ktransformers
< 0.6.3
kvcache-ai/ktransformers
def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca
Published
Jul 20, 2026
Tracked Since
Jul 21, 2026